QID 376377
Date Published: 2022-02-17
QID 376377: Foxit Reader Use After Free Vulnerability
Foxit Reader is a multilingual freemium PDF tool that can create, view, edit, digitally sign, and print PDF files.
Affected Versions:
Foxit PDF Reader earlier to 11.2.1.53537
Foxit PDF Editor 11.2.0.53415 and all previous 11.x versions, 10.1.6.37749 and earlier
A remote attacker can trick the victim to open a specially crafted PDF file, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Solution
The vendor has issued a fix (11.2.1). The updates can be downloaded from Foxit Download Web site.
Vendor References
- Release Note -
www.foxit.com/pdf-reader/version-history.html
CVEs related to QID 376377
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Foxit Reader |
|